Back to resources

How to Spot a Fake Login Page

One of the most common ways people lose their passwords is by putting them into a fake login page. These fake login pages are made to look the same as the real login pages, so you most likely can’t tell the difference between the real and fake by just looking at the login page. Thankfully, there are reliable ways to tell if a login page is real or fake, but only if you know what to check.

Why fake login pages work

Hackers can copy a real website almost perfectly. They use the logos, the colors, the fonts, and the layout of the real website. When you go on their fake version of the website, it looks exactly like the real login page. You type your username and password, but, instead of logging you in, the fake login page actually sends your username and password to the hacker .

Because the visual copy is so good, you can’t depend on how the login page looks. You have to look at things the hacker can’t fake as easily.

Check the web address first

The most important thing to check is the web address in your browser’s address bar. hackers can’t use the exact address as the real website, so they use ones that are close but not exactly right:

  • Misspellings, like “paypa1” with a “1”instead of an “l”.
  • Extra words, like “secure-yourbank-login.com” instead of the real bank address.
  • Different endings, like “.net” instead of “.com”, or odd country codes.
  • The real name is just inside a longer, fake address.

Read the address carefully, character by character if you need to. The real domain is the part right before the first “/”. If that part is not exactly right, leave the page, because it’s a fake login page.

Look for the connection lock, but do not trust it alone

A secure site shows a lock icon and “https” in the address bar, which means your connection is encrypted. This is good to check, but be careful: hackers can get that lock icon for their fake sites too. The lock means your connection is private, not that it’s a real website. So, check the lock, but never rely on just the lock icon. The web address is more important.

How you ended up on the page matters

Ask yourself how you got onto the page. Did you type the address yourself or use a bookmark? Then you are probably fine. Did you click a link in an email, text, or message? Then be suspicious. Fake login pages are usually reached through links designed to trick you.

A safe habit is to never log in through links in messages. Instead, open the site yourself by typing the address or using the official app. This habit stops most fake login attacks from happening to you.

Let your password manager check for you

Thus is one of the most useful features of a password manager, and it stops you from going to fake login pages. A password manager remembers the exact web address where you saved each login. It will only fill in your password on that exact real site, never any fake website.

So if you land on a fake page, even a perfect visual copy, the password manager sees that the address is wrong and does not autofill. That is a really big and important warning. If your password manager will not fill in a login you expected, stop and look closely at the address. You are probably on a fake site.

Your eyes can be fooled by a perfect copy. Your password manager checks the actual address, which the fake site can’t copy.

With HatePassword, your saved logins fill in only on the real sites you saved them for. Add that with the habit of checking the web address and avoiding links in messages, and you will never fall for a fake login page again. They depend on you not looking closely. When you look closely, they fall apart.